SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60302 2026-07-21

CVE-2026-60302: Critical Unauthenticated Takeover in Oracle Coherence

"Oracle disclosed a critical (CVSS 9.8) flaw in Oracle Coherence that lets an unauthenticated attacker with network access fully compromise the product over TCP."

Oracle disclosed a critical (CVSS 9.8) flaw in Oracle Coherence that lets an unauthenticated attacker with network access fully compromise the product over TCP.

What Is It

CVE-2026-60302 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks can result in complete takeover of Oracle Coherence.

The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, low attack complexity, network reachability, and a full-takeover outcome makes this among the most severe classes of vulnerability. An attacker who can reach an exposed Coherence instance over TCP can seize control without credentials or user interaction, threatening the confidentiality, integrity, and availability of the affected system.

Note: The supplied CISA KEV entry is empty, so there is no confirmation of active exploitation at this time.

What's Vulnerable

Per the NVD record, the affected supported versions of Oracle Coherence (Oracle Corporation) are:

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running any affected version should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). No separate CISA KEV required-action or due date was supplied in the source material.

Sources